Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in CARE 2002 before beta 1.0.02 allow remote attackers to perform unauthorized database operations.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CARE 2002多个远程可插入SQL命令漏洞
Vulnerability Description
CARE 2002是一款集成的健康护理一体软件,提供由PHP实现的WEB接口。 CARE 2002对用户提交给数据库的输入缺少正确的验证检查,远程攻击者可以利用这个漏洞进行SQL命令插入攻击。 CARE 2002对用户提供的数据传递给mysqld时,没有很好的检查控制字符如"'",攻击者可以提交包含恶意SQL查询的数据传递给CARE 2002处理,可导致执行更改数据库数据,查看数据库信息等操作。
CVSS Information
N/A
Vulnerability Type
N/A